Infection Channel: Dropped by other malware
This Trojan may be dropped by other malware.
It connects to certain URLs. It may do this to remotely inform a malicious user of its installation. It may also do this to download possibly malicious files onto the computer, which puts the computer at a greater risk of infection by other threats.
It deletes the initially executed copy of itself.
File size: 65,536 bytes
File type: EXE
Memory resident: No
Initial samples received date: 10 May 2012
Payload: Connects to URLs/IPs
Arrival Details
This Trojan may be dropped by the following malware:
Installation
This Trojan drops the following copies of itself into the affected system and executes them:
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Autostart Technique
This Trojan drops the following shortcut pointing to its copy in the User Startup folder to enable its automatic execution at every system startup:
- %User Startup%\Internet Explorer.lnk
(Note: %User Startup% is the current user's Startup folder, which is usually C:\Windows\Profiles\{user name}\Start Menu\Programs\Startup on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Start Menu\Programs\Startup on Windows NT, and C:\Documents and Settings\{User name}\Start Menu\Programs\Startup.)
Download Routine
This Trojan connects to the following malicious URLs:
- http://{BLOCKED}e.support-microsoft.net
Other Details
This Trojan deletes the initially executed copy of itself
Connect with us on
| | | |